CVE-2010-1822
published 2010-10-04CVE-2010-1822: WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3 and Google Chrome before 6.0.472.62, does not properly perform a cast of an unspecified…
PriorityP334high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.18%
80.5th percentile
WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3 and Google Chrome before 6.0.472.62, does not properly perform a cast of an unspecified variable, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an SVG element in a non-SVG document.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | < 4.1.3 | 4.1.3 |
| apple | safari | >= 5.0 < 5.0.3 | 5.0.3 |
| chrome | < 6.0.472.62 | 6.0.472.62 | |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-whwc-x4m2-68jw: WebKit, as used in Apple Safari before 4
ghsa_unreviewed·2022-05-13
CVE-2010-1822 [HIGH] CWE-704 GHSA-whwc-x4m2-68jw: WebKit, as used in Apple Safari before 4
WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3 and Google Chrome before 6.0.472.62, does not properly perform a cast of an unspecified variable, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an SVG element in a non-SVG document.
Red Hat
WebKit: DoS (crash) by processing certain SVG images
vendor_redhat·2010-09-17·CVSS 8.8
CVE-2010-1822 [HIGH] WebKit: DoS (crash) by processing certain SVG images
WebKit: DoS (crash) by processing certain SVG images
WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3 and Google Chrome before 6.0.472.62, does not properly perform a cast of an unspecified variable, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an SVG element in a non-SVG document.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-1822 WebKit: DoS (crash) by processing certain SVG images [fedora-all]
bugzilla·2010-10-22·CVSS 8.8
CVE-2010-1822 [HIGH] CVE-2010-1822 WebKit: DoS (crash) by processing certain SVG images [fedora-all]
CVE-2010-1822 WebKit: DoS (crash) by processing certain SVG images [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=640290
Please note: this issue affects mul
Bugzilla
CVE-2010-1822 WebKit: DoS (crash) by processing certain SVG images
bugzilla·2010-10-05·CVSS 8.8
CVE-2010-1822 [HIGH] CVE-2010-1822 WebKit: DoS (crash) by processing certain SVG images
CVE-2010-1822 WebKit: DoS (crash) by processing certain SVG images
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-1822 to
the following vulnerability:
WebKit, as used in Google Chrome before 6.0.472.62, does not properly
perform a cast of an unspecified variable, which allows remote
attackers to have an unknown impact via a malformed SVG document.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1822
[2] http://code.google.com/p/chromium/issues/detail?id=55114
[3] http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_17.html
[4] https://bugs.webkit.org/show_bug.cgi?id=45562
Discussion:
This doesn't affect webkitgtk 1.2.5:
SVGGElement::rendererIsNeeded should return false when parent isn't SVG
https://bugs.webkit.org/s
http://code.google.com/p/chromium/issues/detail?id=55114http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_17.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/42314http://secunia.com/advisories/43068http://support.apple.com/kb/HT4455http://support.apple.com/kb/HT4456http://www.vupen.com/english/advisories/2010/3046http://www.vupen.com/english/advisories/2011/0212https://bugs.webkit.org/show_bug.cgi?id=45562https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6691http://code.google.com/p/chromium/issues/detail?id=55114http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_17.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/42314http://secunia.com/advisories/43068http://support.apple.com/kb/HT4455http://support.apple.com/kb/HT4456http://www.vupen.com/english/advisories/2010/3046http://www.vupen.com/english/advisories/2011/0212https://bugs.webkit.org/show_bug.cgi?id=45562https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6691
2010-10-04
Published